And that is what makes then so difficult to spot by AV solutions. In this particular case, the Firefox and Chrome extensions are not detected by one single AV solution used by VirusTotal.

Luckily for the users who have installed one of them, the extensions currently simply inject an invisible iframe in each new page that is loaded.

“The iframe contains advertising from resultsz.com, and contains a username in the URL. This tells me that the adware author gets money for the traffic sent to this site, even if the infected user cannot actually see what is being loaded,” says Sobrier, but points out that the remote file can be changed at any moment, allowing the author to steal cookies, login credentials, and more.